Privacy policy
Last updated August 26, 2026
The short version
Show the Play has no advertising, no third-party analytics SDK and no cross-site tracking. We count app usage anonymously ourselves — see Anonymous usage counts below. Adult coaches may use a private account to sync a team. Team workspaces are isolated by server-side access rules; one team cannot see another.
Coach accounts
We store the adult coach’s email address, account identifier, teams joined and role on each team. Players do not create accounts.
Private team information
A team workspace may include a team name, optional crest and colors, players’ first names, jersey numbers and colors, lineups, custom plays, learning progress, game plans and game records. A local copy stays on the coach’s device for offline use. For signed-in teams, a copy is sent over encrypted connections to Show the Play’s managed database so that authorized coaches on that team can share it.
Parents and children
The parent view is read-only and does not require a child account. A parent link contains a compact first-name-only roster and coaching setup in the URL fragment, which ordinary website requests do not receive. Anyone holding the link can view that team copy, so coaches should send it only to team families. A family’s selected player remains on its own device.
A parent link may also carry the coach’s first name, so the app can say “Coach Sam invites you to join the Eagles” instead of showing you a blank screen. That is the first word of the display name the coach set for themselves. It is never an email address, is never worked out from one, and is simply not in the link if the coach never set a name.
Finding a team by name, and asking to join
If nobody sent you a parent link, you can search for your team by name on the app’s first screen and ask the coach to let you in. Here is exactly what that puts on a server, and for how long.
What can be found. Each coach decides whether their team is listed. The switch is Team → Share → “Let families find us in search” and it starts on. While it is on, searching part of the team’s name can show you that team’s name, initials, two team colors and the coach’s first name — never an email address or any piece of one. Switch it off and the team disappears from search straight away; the coach can still add families by sending them the parent link. Nothing else is ever searchable: no roster, no child, no play, no lineup, no game, not even how many people are on a team or whether anybody is.
A team’s own page. While that same switch is on, the team also has a page at a short web address — for example showtheplay.com/team/82h6qdw — which the coach can copy from Team → Share and send to their families. It shows exactly the same five things a search result shows — name, initials, the two team colors and the coach’s first name — plus a button to ask to join, and nothing else. You cannot list or browse teams from it. The short code names the team the way a search result does; it is not a password and protects nothing, because there is nothing behind it that a name search would not already show. Turn the switch off and the page says the team is not listed, whoever holds the link.
What your request stores. Asking to join stores the first name you type for yourself and, if you fill it in, your player’s first name — that one is optional and exists only so your coach can tell who is asking (“Dana, Jaxson’s family”). It also stores the random install ID described under Anonymous usage counts, and which team you asked. No email address, no phone number, no last name, no message.
Who sees it, and for how long. Only the adult coaches of the team you asked can read your request. Nobody else can read it, list it, or find out that it exists — not other families, not other teams. It is deleted the moment a coach declines, with no record kept; it is deleted once an approved family’s device has collected it; and anything still sitting on the server after 7 days is deleted no matter what. You are never shown a rejection.
What approval sends you. Approving hands your device the same read-only copy the coach would have texted you — the parent link described above, built on the coach’s own phone. The server only passes it along; it never puts team information together itself.
Owner usage dashboard
The product owner can see team name, number of adult coaches, app version, last activity time, how many times a share button was pressed (never who a link was sent to), app opens and number of plays shown. The owner dashboard is intentionally not permitted to open team roster snapshots, players, lineups, playbooks, progress or game records.
Anonymous usage counts
We count how many devices use the app, including people who never create an account — guest coaches and families opening a parent link. This is how we know whether the app works and is being used. There is no advertising, no third-party analytics SDK, no advertising identifier and no cross-site tracking.
Everything that is sent, in full: a random install ID generated on the device (not a device identifier, not derived from anything about the phone or the person, not linked to any account, cleared when the app is cleared); which kind of screen the device uses (coach, parent or guest); the app version; counters for app opens, plays shown, share-button presses and how many separate days the app has been used; the short code from a coach’s invite link; an approximate area (country, state and nearest city, worked out from the internet connection by our website host at about the accuracy of a weather forecast — the app cannot request your device’s location and we do not store the internet address); and total time the app has been open and visible on the device (a single running total — the clock stops when the app is hidden). We also record, once, how a device arrived: the invite code it opened with, the domain of the site that linked here (for example “facebook.com” — never a full address or search terms), and whether it is an iPhone or iPad, an Android phone, or a computer.
How the app is used. The app also records which of its own buttons and screens are used, in order, within a visit — for example “opened the board, picked a play, showed the play”. Each entry is an action name from a fixed list plus, at most, a play number; there is no field in which text, a name or anything typed can be sent. These records are attached to the same random install ID, are kept for 90 days and then deleted, and are stamped to the minute; they record when the app was used, never who a person is. They tell us which features work and where people get stuck. They cannot identify a person and contain nothing about any child.
What is never sent: no child’s name, initial, jersey number, colour, photo or position, and no count of children. No roster, lineup, playbook, play name, team name, game plan or learning progress. No name, email address or phone number. No location, no IP address that we log, no device fingerprint, no contacts and no advertising identifier.
Nothing in an anonymous count identifies a person, and the counts cannot be connected to a coach account, a team or a child. We use them only to understand whether the product is working, and never to contact, profile or advertise to anyone. A device sends at most one count every six hours, and only while the app is open — used with no signal, it sends nothing at all.
Service providers and hosting
Supabase provides account authentication and private database hosting. Ordinary website hosting may record standard request information such as time, browser and IP address. We do not sell data and do not use advertising trackers.
Backups and deletion
A coach may export a private backup containing first names and team data. Guest data can be erased by clearing site storage or uninstalling the app. Signed-in coaches can delete individual team content in the app; during beta, contact the person who provided the invitation to request full team or account deletion.
Questions during the private beta can be sent to the person who provided your invitation.
← Open Show the Play